๐Ÿ” CVE Alert

CVE-2026-107384

HIGH 8.1

MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries)

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can update columns the application did not intend to expose and can append arbitrary SQL with the database user's privileges. The option is disabled by default, and serialized-object handling used when it is disabled is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.

CWE CWE-89
Vendor mariadb-corporation
Product mariadb-connector-nodejs
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for mariadb-corporation mariadb-connector-nodejs

Be the first to know when new high vulnerabilities affecting mariadb-corporation mariadb-connector-nodejs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

mariadb-corporation / mariadb-connector-nodejs
>= 3.2.0, < 3.2.5 >= 3.3.0, < 3.3.4 >= 3.4.0, < 3.4.7 >= 3.5.0-rc.0, < 3.5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-v6pj-gxxw-phfw github.com: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/144b8f4ef29539a9fb4b75d972b9dcdac4088b4e github.com: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6743b2f4a89b074268b44c650170767f35e1fb5d github.com: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/8eb450972ff0f3826d7d45c071a42240798bc826 github.com: https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b9b04ec82a60b2caf2b0c038259ca9aff5d7014a hackerone.com: https://hackerone.com/reports/3889198 github.com: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5 github.com: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4 github.com: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7 github.com: https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4 jira.mariadb.org: https://jira.mariadb.org/browse/CONJS-369